LEGAL

Privacy Policy

Effective date: 1 April 2026  ·  Last updated: 8 April 2026
Plain English summary: We collect only what we need to run the service. We never sell your data. Your financial records are yours — only you can see them. The founder can only access your data when you raise a support request, and that access is logged. Sensitive identifiers are stored as one-way cryptographic hashes, not in plain text. You can delete your account and all your data instantly from Settings — no email needed.

01Who this policy applies to

This Privacy Policy explains how snapbook.ai ("snapbook", "we", "us", "our") collects, uses, and protects information about you when you use our bookkeeping service at snapbook.ai.

By using snapbook.ai, you agree to the practices described in this policy. This policy is governed by the Personal Data Protection Act 2012 (PDPA) of Singapore.

We have appointed a Data Protection Officer responsible for overseeing compliance with the PDPA. For any data protection matters or rights requests, you may contact our DPO at [email protected].

02What data we collect

We collect the following categories of information:

Data type What it includes Why we collect it
Account data Email address, password (encrypted), account creation date To create and manage your account
Business data Business name, business structure type, UEN (registered companies only), GST status, financial year end To personalise the service and pre-fill compliance forms
Telegram integration A one-way cryptographic hash of your Telegram chat ID — the raw ID is never stored To link your Telegram account for mobile receipt capture
Financial records Receipts, invoices, transaction data, amounts, vendors, categories To provide bookkeeping and P&L reporting
Uploaded files Images and PDFs of receipts and financial documents To extract transaction data using AI
Usage data Pages visited, features used, upload counts To improve the service and enforce plan limits

We do not collect your NRIC, passport number, bank account details, or credit card numbers.

03How we use your data

We use your data solely to provide and improve snapbook.ai. Specifically:

  • To process uploaded receipts and extract transaction data using AI
  • To generate your profit and loss reports and expense summaries
  • To manage your account, plan, and usage limits
  • To send you transactional emails such as password resets and account confirmations
  • To improve the accuracy of our AI and fix bugs in the service

We never use your uploaded financial documents, receipts, or transaction data to train AI models. Any use of your data for model improvement would require separate, explicit consent from you. We do not use your data for advertising or marketing profiling.

04Who we share your data with

We do not sell your personal data to third parties. We share data only with the following service providers, strictly to operate the platform:

  • Supabase — database, file storage, and authentication. Your data is stored on Supabase infrastructure hosted on AWS.
  • Anthropic — AI processing. Uploaded receipt images and documents are sent to Anthropic's Claude API to extract transaction data. Anthropic does not retain your data for training purposes under their API terms.
  • Railway — our application hosting provider.

The founder may access your data solely to investigate and resolve support requests raised by you. This access is not used for any other purpose.

We may disclose your data to government authorities or law enforcement if required by Singapore law.

Each of these providers acts as a data intermediary on our behalf. We have agreements in place requiring them to protect your data in accordance with applicable data protection obligations, including the PDPA. We remain responsible for ensuring your data is handled appropriately by these providers.

05Data storage and security

Your data is stored on Supabase infrastructure hosted on Amazon Web Services (AWS) in the ap-southeast-1 (Singapore) region. We take the following measures to protect your data:

  • All data is encrypted in transit using HTTPS/TLS
  • Passwords are hashed and never stored in plain text
  • Row-level security (RLS) is enforced at the database level — each user can only read and write their own data, with no cross-user access possible
  • Sensitive identifiers such as your Telegram chat ID are stored as HMAC SHA256 hashes — the original value cannot be recovered from what we store
  • Uploaded files are stored in private, access-controlled storage buckets
  • The founder may access your data only in response to a support request you raise. Such access is logged with a timestamp and purpose, and is not used for any other reason

No security system is perfect. While we take reasonable precautions, we cannot guarantee absolute security of your data.

In the event of a data breach affecting your personal data, we will assess the incident promptly and in accordance with our obligations under the PDPA. If the breach is notifiable, we will inform the Personal Data Protection Commission (PDPC) within the required timeframe and notify affected users if there is likely risk of significant harm.

06How long we keep your data

We retain your data for as long as your account is active. When you delete your account via Settings → Delete Account, your personal data, financial records, uploaded files, and all associated data are deleted immediately. Backup copies are retained for up to 7 days as part of our infrastructure recovery process and are permanently purged thereafter. We may retain certain transaction records beyond account deletion where required by Singapore law, including for tax and IRAS compliance purposes.

07Your rights under the PDPA

Under Singapore's Personal Data Protection Act 2012, you have the right to:

  • Access the personal data we hold about you
  • Correct any inaccurate personal data
  • Withdraw consent to the collection or use of your personal data (note: this may affect your ability to use the service)
  • Request deletion of your account and associated data

You can delete your account and all associated data — receipts, transactions, payroll records, and settings — instantly via Settings → Delete Account. No email required. For all other rights requests, email us at [email protected] and we will respond within 10 business days.

08Cookies and analytics

snapbook.ai uses the following analytics tools to understand how the service is used: Microsoft Clarity (session recording and heatmaps), Google Analytics (page and event tracking), and Meta Pixel (conversion tracking). These tools may use cookies or browser local storage. We also use local storage to remember your theme preference (light or dark).

Your financial data is never shared with these analytics providers. We do not use advertising cookies or track you across other websites for marketing profiling purposes.

09Children's privacy

snapbook.ai is not intended for use by anyone under the age of 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us and we will delete it promptly.

10Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. If changes are material, we will notify you by email. Continued use of snapbook.ai after changes take effect constitutes acceptance of the updated policy.

Questions or data requests?

[email protected]